SonicWall: Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

SonicWall: Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

SonicWall VPN and Firewall Accounts Hit by Rapid Credential Stuffing Attack

Huntress researchers uncovered an active credential stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations in under 48 hours. The attacks, which began on Saturday, escalated quickly, breaching 92 unique user accounts within 41 hours before abruptly stopping on Monday.

The campaign appeared broad and opportunistic, affecting various SonicWall devices without targeting specific industries. Attackers leveraged validated credentials against remote access portals, though the exact source whether stolen logs, prior breaches, or unpatched vulnerabilities remains unclear. Notably, no post-compromise activity has been observed, suggesting the intrusions may be pre-positioning for future attacks.

Huntress’s findings are based on telemetry from its customer base, meaning the true scope of affected organizations could be larger. SonicWall has yet to issue an official advisory, though a spokesperson confirmed an ongoing investigation.

This incident follows a pattern of persistent threats against SonicWall devices. In 2025, an undisclosed state-sponsored actor breached SonicWall’s cloud environment, stealing firewall configurations for all customers. The company has also faced multiple zero-day exploits, including two actively exploited flaws patched earlier this month after a three-week window of exposure. Since late 2021, 17 SonicWall vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities Catalog, with 10 linked to ransomware attacks, including a recent surge by the Akira ransomware group.

Edge devices like SonicWall firewalls remain a prime target, accounting for over 70% of active intrusions tracked by Huntress, particularly in ransomware deployments. The attack underscores the risks of unsecured remote access solutions and the ongoing challenges of defending against credential-based threats.

Source: https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/

SonicWall TPRM report: https://www.rankiteo.com/company/sonicwall

"id": "son1785450554",
"linkid": "sonicwall",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'name': '30 organizations (specific names unknown)',
                        'type': 'Organizations using SonicWall VPN/firewall'}],
 'attack_vector': 'Validated credentials against remote access portals',
 'data_breach': {'number_of_records_exposed': '92 unique user accounts'},
 'date_detected': '2023-11-04',
 'description': 'Huntress researchers uncovered an active credential stuffing '
                'campaign targeting SonicWall VPN and firewall accounts, '
                'compromising 30 organizations in under 48 hours. The attacks '
                'breached 92 unique user accounts within 41 hours before '
                'abruptly stopping. The campaign appeared broad and '
                'opportunistic, affecting various SonicWall devices without '
                'targeting specific industries. Attackers leveraged validated '
                'credentials against remote access portals, with no '
                'post-compromise activity observed, suggesting pre-positioning '
                'for future attacks.',
 'impact': {'systems_affected': 'SonicWall VPN and firewall accounts'},
 'initial_access_broker': {'entry_point': 'Remote access portals'},
 'investigation_status': 'Ongoing (SonicWall investigation)',
 'lessons_learned': 'The incident underscores the risks of unsecured remote '
                    'access solutions and the ongoing challenges of defending '
                    'against credential-based threats. Edge devices like '
                    'SonicWall firewalls remain a prime target for ransomware '
                    'deployments.',
 'motivation': 'Pre-positioning for future attacks',
 'post_incident_analysis': {'root_causes': 'Use of validated credentials '
                                           '(source unclear)'},
 'references': [{'source': 'Huntress research'}],
 'response': {'third_party_assistance': 'Huntress researchers'},
 'title': 'SonicWall VPN and Firewall Accounts Hit by Rapid Credential '
          'Stuffing Attack',
 'type': 'Credential Stuffing'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.